CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25597  CVE-2007-2240  Candidate  The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.  Assigned (20070425)  None (candidate not yet proposed)    View
91133  CVE-2016-4314  Candidate  Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.  Assigned (20160427)  None (candidate not yet proposed)    View
25853  CVE-2007-2496  Candidate  The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.  Assigned (20070503)  None (candidate not yet proposed)    View
91389  CVE-2016-4570  Candidate  The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.  Assigned (20160509)  None (candidate not yet proposed)    View
26109  CVE-2007-2752  Candidate  SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20070517)  None (candidate not yet proposed)    View

Page 20741 of 20943, showing 5 records out of 104715 total, starting on record 103701, ending on 103705

Actions